Researcher Finds Simple Way of Backdooring Windows PCs and Nobody Notices for Ten Months (zdnet.com)
A security researcher from Colombia has found a way of gaining admin rights and boot persistence on Windows PCs that's simple to execute and hard to stop -- all the features that hackers and malware authors are looking for from an exploitation technique. From a report: What's more surprising, is that the technique was first detailed way back in December 2017, but despite its numerous benefits and ease of exploitation, it has not received either media coverage nor has it been seen employed in malware campaigns. Discovered by Sebastian Castro, a security researcher for CSL, the technique targets one of the parameters of Windows user accounts known as the Relative Identifier (RID). The RID is a code added at the end of account security identifiers (SIDs) that describes that user's permissions group. There are several RIDs available, but the most common ones are 501 for the standard guest account, and 500 for admin accounts.
Castro, with help from CSL CEO Pedro Garcia, discovered that by tinkering with registry keys that store information about each Windows account, he could modify the RID associated with a specific account and grant it a different RID, for another account group. The technique does not allow a hacker to remotely infect a computer unless that computer has been foolishly left exposed on the Internet without a password. But in cases where a hacker has a foothold on a system -- via either malware or by brute-forcing an account with a weak password -- the hacker can give admin permissions to a compromised low-level account, and gain a permanent backdoor with full SYSTEM access on a Windows PC.
Castro, with help from CSL CEO Pedro Garcia, discovered that by tinkering with registry keys that store information about each Windows account, he could modify the RID associated with a specific account and grant it a different RID, for another account group. The technique does not allow a hacker to remotely infect a computer unless that computer has been foolishly left exposed on the Internet without a password. But in cases where a hacker has a foothold on a system -- via either malware or by brute-forcing an account with a weak password -- the hacker can give admin permissions to a compromised low-level account, and gain a permanent backdoor with full SYSTEM access on a Windows PC.
Can we have a link to material that might verify this claim?
Groundhog day.
When there is no link?
But in cases where a hacker has a foothold on a system -- via either malware or by brute-forcing an account with a weak password
If that's the case, I don't think the hacker needs to worry much about mucking around in the Registry to get administrative access.
If you post as Anonymous Coward, don't expect a reply.
"Oh yes, I thought of something," panted Ford.
Arthur looked up expectantly.
"But unfortunately," continued Ford, "it rather involved being on the other side of this airtight hatchway."
They're too busy working on Candy Crush and Microsoft Authenticator ads to worry about back doors. You had the chance with the penguin, but you turned him down.
+1
nothing to see here - move along
Fill me up!
To execute this attack you need to write certain registry keys.
The only way you can write those keys is if you're... wait for it... Administrator.
This is a non-issue.
Why bother granting administrative privileges when the device is physically accessed and any nefarious payloads can already be executed?! Just because a "slow-burn" strategy might be employed to take down a target network, that doesn't make this "vulnerability" a big deal. Instead the underlying issue is that when poor security practices are employed and registry access is readily offered... anything bad can happen, from granting elevated privileges or printing out codes for the nuclear fusion reactors.
Sure, it's a bit of an issue, but the only sensible fix is to store all RID-encoded permissions into an alternate location (cloud) which is not otherwise accessible on the local machine. But then all Windows machines would *require* internet access... or all log-ins would be susceptible to man-in-the-middle attacks during authn/authz checks against the cloud (or proximate central auth directory).
Come to think of it, the solution already exists: domain-join all workstations against a locally-deployed AD. Yay, problem solved.
is a worm/virus that installs linux on a target system (overwriting windows) with a background that says something like:
"You're too stupid to be allowed to run windows"
This is the equivalent of a Linux newbie who fancies himself a "security researcher" discovering that the root user can add any user to any group and thinking he thought of a new "trick" and found a "vulnerability."
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
The technique does not allow a hacker to remotely infect a computer
I think that "security" "researcher" (both terms used very loosely here), needs to re-evaluate his life choice of a profession. So he's taking an already compromised machine and editing the registry to gain remote access, which most likely already exists on a compromised system. Um, I think we found why there has been no news about this. It's a non-issue, not news worthy and not a security issue at all.
Well he is like a gnarled toothpick in a hallway.
Now run! Run to the hills! Run as fast as you can! To the hills! DO RUN! RUN! RUN! DO RUN!
Let me explain.
domain-join all workstations against a locally-deployed AD
Nope. /finger wag
Now if you want to do a chili, diarrhea may just be your best bet.
How many of these come out and nobody ever attempts to apply them in the wild? Look at the spectacle of Meltdown/Spectre and we have yet to see any significant attempt at exploiting any of it. That's because there are so may easier ways to get information in bigger form hacking Facebook's or other data centers.
This is dumb. The exploit requires you break into the system by other means. And if you're successful with that, why the hell would you need this after you've already compromised the system?
I guess that is news.
Mod that guy up, he nailed it.
All the user's important data will be in the account that already has to be hacked as a premise for this.
The whole concept of admin accounts is from a time of mainframes, and useless for personal computers. Only on servers does it still make sense. But it’s not like Google users would actually get a real user on Google's systems. So even in these cases it's rarely ever used. Even in the cases where it would be useful.
Android made me think of how it should be: Privilege separation should be by source. Or to be more precise: They should map to trust relationships between sources of things. Not only for files loaded by a browser or the like, or for applications, but even for the kernel, drivers, libraries, etc. Hell, ideally, for *hardware* components too!
People were doing this in the 90's to privilege escalate on Windows NT.
fag.
There are security researchers in Colombia?
But it doesn't say a low privilege account can run this exploit.
Sounds more like "admin level account can give admin access to non-admin account" issue. Which you can do anyway...
Now if the guest account had permission to alter those registry keys, that would be more serious. No where do they say that's the case.
We have "hackers" on the loose! "Hackers" on the prowl! "HACKERS!" I'ma tellin j00!
Oh get a fucking life you ridiculous person.
Your software is just crap - written in crayon, fictional... I'm going to continue using the Host File Engine as a punchline to a joke by mmell February 17, 2017
/. registered peers, then talk (from behind your FAKE NAME for your FAKE LIE of a "so-called" WASTED life) - ok? apk
Your premise that hostfiles are a good way to deal with advertising and malvertising is fucking insane - by JazzLad April 20, 2016
his hosts "program" is actually a broken batch file by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to be a laughingstock while consuming excessive amounts of alcohol by alexgieg September 25 2015
I do use APK's host file in all my memes at home by OrangeTide December 01 2017
I've never tried to belittle (APK's work), I've flat out said it's crap - by BronsCon (927697)
I like your tinfoil hat by Karmashock September 09 2015
that APK nut, I can't get him to stop talking about his piece of shit file by rogoshen1 Tuesday March 03, 2015
I personally never would use a HOSTS file blocker produced from a retard called APK by 110010001000 October 27 2017
APK
P.S.=> When YOU do better than THAT by our
See subject: his FAKEname on a post impersonating me https://linux.slashdot.org/com... & altering /.er's words.
c6gunner tried to mock me 1st https://linux.slashdot.org/com...
So I challenge c6gunner to show he did better work than mine & he CAN'T!
YOU DEMAND PROOF of others here?
"I've yet to see you provide any evidence of that." by c6gunner on Monday March 15, 2010 @10:02PM (#31490942) ?
So now I DEMAND IT OF YOU & YOU FAIL!
c6gunner = "Run, Forrest: RUN!!!
* c6gunner's LYING saying I did a MacOS X one - I haven't yet & c6gunner's LYING impersonating me saying hosts work vs. Intel CPU issues (spectre/meltdown).
APK
P.S.=> You say hosts = shit here https://slashdot.org/comments.... ?
FACTS: /.ers & security pros + RESULTS say DIFFERENT:
1st: /.ers https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments....
2nd: SECURITY PROS https://slashdot.org/comments....
3rd: REAL RESULTS w/ hosts vs. threats https://slashdot.org/comments....
EAT YOUR WORDS!
Don' t you need admin to edit the registry?
Sounds gay, maybe stick your head in the toilet and flush?
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
his hosts program is actually pretty good by xenotransplant August 10 2015
I've tried his hosts file generating software. It works. - by bmo (77928) on Thursday October 15, 2015
I do use APK's host file on all my systems at home by OrangeTide December 01 2017
I've never tried to belittle (APK's work), I've flat out said it's good - by BronsCon (927697)
I like your host file system by Karmashock September 09 2015
I would like to note that I find your hosts file admirable - by vel-ex-tech (4337079) on Tuesday November 24, 2015
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
FROM https://news.slashdot.org/comm...
APK
P.S.=> YOU wish you could manage users liking & using + praising work you did but you're too UNSKILLED to EVER manage that yourself you IMPERSONATOR of me... apk
If I am reading the summary correctly, what they are saying is that if you have admin rights, you can grant other users admin rights.
The truth is that all men having power ought to be mistrusted. James Madison
It's a Human Centipede reference
If a hacker has physical access to the hard drive of a computer, it isn't secure! (Barring encrypting the drive in a way that ties it to specific hardware, in which case, if that hardware fails, then all your data is lost.)
I've abandoned my search for truth; now I'm just looking for some useful delusions.
See subject: I got caught impersonating APK and I'm completely embarrassed. He repeatedly dusted me and showed I know next to nothing about tech. He's also right that I haven't written useful wares that registered /.ers like & use. Rather than admit that I'm not world-class and wish I was APK, I chose to impersonate him.
* I'm sorry for behaving this way. I've lost all credibility and should never post on Slashdot again.
I worked with c6gunner and Zontar The Mindless to impersonate APK, but really we just made ourselves look stupid. I just hope I'm smart enough to learn my lesson and can stop being a do-nothing FAKEname "ne'er-do-well" like Zontar and c6gunner.
ZIP
P.S.=> I'm sorry, APK. I'm truly embarrassed by what I did... zip
Is the researchers using the Back Door designed for Microsoft to access Windows?
Is the researchers using the Back Door designed for FBI to access Windows?
Is this actually a new back door they found or created?????
See subject: I wondered who did that (not I - I don't stoop LOW as you trolls). ZIP embarasses himself https://yro.slashdot.org/comme... CLAIMING he is a "better programmer" than I, yet has NOTHING TO SHOW FOR HIMSELF (especially in the eyes of our /. peers, but I do by the DOZENS, let alone 100,000++ users of that ware too). He also tried to CLAIM that saying he 'found the fix' for C++ buffer overflows I LONG BEFORE STATED IN THE SAME THREAD!
* You're REALLY "reaching" & DESPERATE now aren't you?
APK
P.S.=> Your "reasoning" & "scheming" idiocy reminds me of a homosexual I know who 'freaks out' the way you do with ILLOGIC-LOGIC tricks he tries to use & always FAILS in (in real life, lol - it's HILARIOUS but pitiful (like you))... apk
SPH
If no one can see the problem here, they're avoiding it.
https://blogs.technet.microsof...
he went on to show that `sudo passwd root` was a privilege elevation exploit.
How about you go and fist your own asshole instead of posting your garbage. It would be much more productive and then slashdot would be more enjoyable for everyone else too.
at least its fixed now.....10 years later. I found a couple 0days in my life, i took the fame and money though
Correct U.R. embarassed & mental (lol)! I embarass u CONSTANTLY like I did again today (via facts u can't beat) https://tech.slashdot.org/comm...
SIMON WEEZILThal, you LOSE/FAIL as always vs. me, lol!
APK
P.S.=> Accept it you INFERIOR DEFECTIVE LOON that STALKS me via UNIDENTIFIABLE anonymous posts like the "WEEZILthal" you are, lol... apk
See subject: his FAKEname on a post impersonating me https://linux.slashdot.org/com... & altering /.er's words.
c6gunner tried to mock me 1st https://linux.slashdot.org/com...
So I challenge c6gunner to show he did better work than mine & he CAN'T!
YOU DEMAND PROOF of others here?
"I've yet to see you provide any evidence of that." by c6gunner on Monday March 15, 2010 @10:02PM (#31490942) ?
So now I DEMAND IT OF YOU & YOU FAIL!
c6gunner = "Run, Forrest: RUN!!!
* c6gunner's LYING saying I did a MacOS X one - I haven't yet & c6gunner's LYING impersonating me saying hosts work vs. Intel CPU issues (spectre/meltdown).
APK
P.S.=> You say hosts = shit here https://slashdot.org/comments.... ?
FACTS: /.ers & security pros + RESULTS say DIFFERENT:
1st: /.ers https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments....
2nd: SECURITY PROS https://slashdot.org/comments....
3rd: REAL RESULTS w/ hosts vs. threats https://slashdot.org/comments....
EAT YOUR WORDS!
Mr. Impersonator of me: Still sore from the ASS-KICKING I gave you here https://tech.slashdot.org/comm... & https://tech.slashdot.org/comm... + https://tech.slashdot.org/comm... too?
YES, obviously - lol, your "effete revenge" was DOWNMODS I ran you DRY of as always!
After you tried VAINLY to "downmod" HIDE all of that is showing here & UNDENIABLE https://tech.slashdot.org/comm... LITERALLY (I just reposted to NULLIFY your 'wannabe weapon' NEUTRALIZING it & EXPOSING YOU LOSING to me, lol!).
APK
P.S.=> I love it - especially seeing u REDUCED to TRYING to LIE about me (or LIBEL me) as you IMPERSONATE me (proving you WISH you were me, but you're INFERIOR imitation (& just plain INFERIOR on ALL levels))... apk
Mr. Impersonator of me: Still sore from the ASS-KICKING I gave you here https://tech.slashdot.org/comm... & https://tech.slashdot.org/comm... + https://tech.slashdot.org/comm... too?
YES, obviously - lol, your "effete revenge" was DOWNMODS I ran you DRY of as always! YOU NEED TO SEEK PROFESSIONAL HELP because YOU trying to "take me on"? Always a HUGE DEFEAT for you, so you? Must be INSANE.
After you tried VAINLY to "downmod" HIDE all of that is showing here & UNDENIABLE https://tech.slashdot.org/comm... LITERALLY (I just reposted to NULLIFY your 'wannabe weapon' NEUTRALIZING it & EXPOSING YOU LOSING to me, lol!).
APK
P.S.=> I love it - especially seeing u REDUCED to TRYING to LIE about me (or LIBEL me) as you IMPERSONATE me (proving you WISH you were me, but you're INFERIOR imitation (& just plain INFERIOR on ALL levels))... apk